This is a hidden feature that was worked in last summer but currently if you do not include CN=$PROFILE_IDENTIFIER in the subject name for the certificate your certificate will expire and never renew. When you add CN=$PROFILE_IDENTIFIER to the subject name then click on General mandatory you will have an option below Level computer/user drop down that appears "Redeploy Profile". This is how frequent it will redeploy the profile which will delete the existing Certificate and deliver a new certificate.
One thing to consider is like in our environment you have to be on the network to see our CA. So I have our profile scoped to all computer but they have to be on networks that have access to the CA. This way if they do not have access to the network it doesn't remove the certificate leaving the user unable to connect to our VPN solution.